Advanced Search
CS Search Google Search
Subscribers, please login

Published Articles >> Table of Contents >> Abstract

DARPA Information Survivability Conference and Exposition - Volume II   p. 234
A Flexible Architecture for Security Policy Enforcement

Full Article Text: Download PDF of full textBuy this articleGet full text from IEEE Xplore

DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/DISCEX.2003.1194971
Send link to a friend

Abstract
Significant progress has been made on the design of security policy representations for complex communication systems. A significant problem however remains - how to design software architectures that enforce ever- changing security policy requirements efficiently. This research summary describes the security policy enforcement architecture of the Antigone 2.0 the group communication system. The architecture is designed to be flexible: new security mechanism modules are added as needed to support emerging policy requirements. Such mechanisms regulate the processing of system and network events as directed by the policy and enforce fine- grained control over sensitive data. A software bus is used coordinate the delivery of these events to mechanisms within each process. We summarize an analysis of the performance of the architecture and show that the overheads are modest for typical environments.
Additional Information

Citation:  Patrick McDaniel, Atul Prakash, "A Flexible Architecture for Security Policy Enforcement," discex, p. 234,  DARPA Information Survivability Conference and Exposition - Volume II,  2003

Similar Articles

Abstract Contents
Abstract
Citation




Free access to

  • Abstracts
  • Selected PDFs

Electronic subscribers login to:

  • Access HTML/PDFs of full text articles

Subscription information

Get a Web account

PDFs require Adobe Acrobat Reader.

Peer Review Notice

Give us Feedback